{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,4]],"date-time":"2025-11-04T16:22:03Z","timestamp":1762273323700,"version":"3.41.0"},"reference-count":39,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2024,12,11]],"date-time":"2024-12-11T00:00:00Z","timestamp":1733875200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["J. Data and Information Quality"],"published-print":{"date-parts":[[2024,12,31]]},"abstract":"<jats:p>Transformer-based models have demonstrated much success in various natural language processing tasks. However, they are often vulnerable to adversarial attacks, such as data poisoning, which can intentionally fool the model into generating incorrect results. In this article, we present a novel, compound variant of a data poisoning attack on a transformer-based model that maximizes the poisoning effect while minimizing the scope of poisoning. We do so by combining the established data poisoning technique (label flipping) with a novel adversarial artifact selection and insertion technique aimed at minimizing detectability and the scope of the poisoning footprint. We find that by using a combination of these two techniques, we achieve a state-of-the-art attack success rate of approximately 90% while poisoning only 0.5% of the original training set, thus minimizing the scope and detectability of the poisoning action. These findings have the potential to advance the development of better data poisoning detection methods.<\/jats:p>","DOI":"10.1145\/3705897","type":"journal-article","created":{"date-parts":[[2024,11,27]],"date-time":"2024-11-27T09:51:27Z","timestamp":1732701087000},"page":"1-15","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["A Compound Data Poisoning Technique with Significant Adversarial Effects on Transformer-based Sentiment Classification Tasks"],"prefix":"10.1145","volume":"16","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2173-3663","authenticated-orcid":false,"given":"Edmon","family":"Begoli","sequence":"first","affiliation":[{"name":"Oak Ridge National Laboratory, Oak Ridge, United States"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3422-9650","authenticated-orcid":false,"given":"Maria","family":"Mahbub","sequence":"additional","affiliation":[{"name":"Oak Ridge National Laboratory, Oak Ridge, United States"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9808-3515","authenticated-orcid":false,"given":"Linsey","family":"Passarella","sequence":"additional","affiliation":[{"name":"Oak Ridge National Laboratory, Oak Ridge, United States"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1222-7512","authenticated-orcid":false,"given":"Sudarshan","family":"Srinivasan","sequence":"additional","affiliation":[{"name":"Oak Ridge National Laboratory, Oak Ridge, United States"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,12,11]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.23919\/FRUCT56874.2022.9953823"},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-16-8059-5_36"},{"key":"e_1_3_1_4_2","article-title":"BadPre: Task-agnostic backdoor attacks to pre-trained NLP foundation models","author":"Chen Kangjie","year":"2021","unstructured":"Kangjie Chen, Yuxian Meng, Xiaofei Sun, Shangwei Guo, Tianwei Zhang, Jiwei Li, and Chun Fan. 2021. BadPre: Task-agnostic backdoor attacks to pre-trained NLP foundation models. arXiv e-printsarXiv:2110.02467 (2021).","journal-title":"arXiv e-prints"},{"key":"e_1_3_1_5_2","volume-title":"Proceedings of the ICML 2021 Workshop on Adversarial Machine Learning","author":"Chen Xiaoyi","year":"2021","unstructured":"Xiaoyi Chen, Ahmed Salem, Michael Backes, Shiqing Ma, and Yang Zhang. 2021. BadNL: Backdoor attacks against NLP models. In Proceedings of the ICML 2021 Workshop on Adversarial Machine Learning. https:\/\/openreview.net\/forum?id=v6UimxiiR78"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/3585385"},{"key":"e_1_3_1_7_2","unstructured":"European Commission. 2023. Artificial Intelligence\u2014Questions and Answers. Retrieved January 14 2024 from https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/qanda_21_1683"},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2941376"},{"key":"e_1_3_1_9_2","unstructured":"Jacob Devlin Ming-Wei Chang Kenton Lee and Kristina Toutanova. 2019. BERT: Pre-training of deep bidirectional transformers for language understanding. arXiv:abs\/1810.04805 (2019)."},{"key":"e_1_3_1_10_2","unstructured":"Micah Goldblum Dimitris Tsipras Chulin Xie Xinyun Chen Avi Schwarzschild Dawn Song Aleksander Madry Bo Li and Tom Goldstein. 2020. Dataset security for machine learning: Data poisoning backdoor attacks and defenses. arXiv:2012.01544 (2020)."},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/3593042"},{"key":"e_1_3_1_12_2","unstructured":"Tianyu Gu Brendan Dolan-Gavitt and Siddharth Garg. 2017. BadNets: Identifying vulnerabilities in the machine learning model supply chain. arXiv:1708.06733 (2017)."},{"key":"e_1_3_1_13_2","doi-asserted-by":"publisher","DOI":"10.1609\/icwsm.v8i1.14550"},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i05.6311"},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-40837-3_1"},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-95391-1"},{"key":"e_1_3_1_17_2","unstructured":"Yiming Li Yong Jiang Zhifeng Li and Shu-Tao Xia. 2022. Backdoor learning: A survey. arXiv e-prints arXiv:2007.08745 (2022)."},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.5555\/2002472.2002491"},{"key":"e_1_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.5555\/2002472.2002491"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2021.09.130"},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1018"},{"key":"e_1_3_1_22_2","article-title":"Mind the style of text! Adversarial and backdoor attacks based on text style transfer","author":"Qi Fanchao","year":"2021","unstructured":"Fanchao Qi, Yangyi Chen, Xurui Zhang, Mukai Li, Zhiyuan Liu, and Maosong Sun. 2021. Mind the style of text! Adversarial and backdoor attacks based on text style transfer. arXiv preprint arXiv:2110.07139 (2021).","journal-title":"arXiv preprint arXiv:2110.07139"},{"key":"e_1_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.37"},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"e_1_3_1_25_2","first-page":"9389","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Schwarzschild Avi","year":"2021","unstructured":"Avi Schwarzschild, Micah Goldblum, Arjun Gupta, John P. Dickerson, and Tom Goldstein. 2021. Just how toxic is data poisoning? A unified benchmark for backdoor and data poisoning attacks. In Proceedings of the International Conference on Machine Learning. 9389\u20139398."},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/QRS57517.2022.00086"},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW53761.2021.00049"},{"key":"e_1_3_1_28_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In Proceedings of the International Conference on Learning Representations. http:\/\/arxiv.org\/abs\/1312.6199"},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-020-04831-9"},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00402"},{"key":"e_1_3_1_31_2","article-title":"Attention is all you need","volume":"30","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N. Gomez, \u0141ukasz Kaiser, and Illia Polosukhin. 2017. Attention is all you need. Advances in Neural Information Processing Systems 30 (2017), 1\u201311.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_1_32_2","article-title":"Concealed data poisoning attacks on NLP models","author":"Wallace Eric","year":"2020","unstructured":"Eric Wallace, Tony Z. Zhao, Shi Feng, and Sameer Singh. 2020. Concealed data poisoning attacks on NLP models. arXiv e-printsarXiv:2010.12563 (2020).","journal-title":"arXiv e-prints"},{"key":"e_1_3_1_33_2","article-title":"HuggingFace\u2019s Transformers: State-of-the-art natural language processing","author":"Wolf Thomas","year":"2019","unstructured":"Thomas Wolf, Lysandre Debut, Victor Sanh, Julien Chaumond, Clement Delangue, Anthony Moi, Pierric Cistac, Tim Rault, R\u00e9mi Louf, Morgan Funtowicz, et\u00a0al. 2019. HuggingFace\u2019s Transformers: State-of-the-art natural language processing. arXiv e-printsarXiv:1910.03771 (2019).","journal-title":"arXiv e-prints"},{"key":"e_1_3_1_34_2","volume-title":"Proceedings of the 20th European Conference on Artificial Intelligence (ECAI \u201912)","author":"Xiao Han","year":"2012","unstructured":"Han Xiao, Huang Xiao, and Claudia Eckert. 2012. Adversarial label flips attack on support vector machines. In Proceedings of the 20th European Conference on Artificial Intelligence (ECAI \u201912). 870\u2013875."},{"key":"e_1_3_1_35_2","article-title":"Rethinking label flipping attack: From sample masking to sample thresholding","author":"Xu Qianqian","year":"2022","unstructured":"Qianqian Xu, Zhiyong Yang, Yunrui Zhao, Xiaochun Cao, and Qingming Huang. 2022. Rethinking label flipping attack: From sample masking to sample thresholding. IEEE Transactions on Pattern Analysis and Machine Intelligence 45, 6 (2022), 7668\u20137685.","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.431"},{"key":"e_1_3_1_37_2","article-title":"A survey on Large Language Model (LLM) security and privacy: The good, the bad, and the ugly","author":"Yao Yifan","year":"2023","unstructured":"Yifan Yao, Jinhao Duan, Kaidi Xu, Yuanfang Cai, Eric Sun, and Yue Zhang. 2023. A survey on Large Language Model (LLM) security and privacy: The good, the bad, and the ugly. arXiv preprint arXiv:2312.02003 (2023).","journal-title":"arXiv preprint arXiv:2312.02003"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10489-020-02086-4"},{"key":"e_1_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00022"},{"key":"e_1_3_1_40_2","article-title":"Character-level convolutional networks for text classification","volume":"28","author":"Zhang Xiang","year":"2015","unstructured":"Xiang Zhang, Junbo Zhao, and Yann LeCun. 2015. Character-level convolutional networks for text classification. Advances in Neural Information Processing Systems 28 (2015), 1\u20139.","journal-title":"Advances in Neural Information Processing Systems"}],"container-title":["Journal of Data and Information Quality"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3705897","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3705897","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:18:13Z","timestamp":1750295893000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3705897"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,11]]},"references-count":39,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2024,12,31]]}},"alternative-id":["10.1145\/3705897"],"URL":"https:\/\/doi.org\/10.1145\/3705897","relation":{},"ISSN":["1936-1955","1936-1963"],"issn-type":[{"type":"print","value":"1936-1955"},{"type":"electronic","value":"1936-1963"}],"subject":[],"published":{"date-parts":[[2024,12,11]]},"assertion":[{"value":"2023-06-13","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-10-08","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-12-11","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}